Security Advisory

CVE-2015-5887

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-10-09 01:00:00
Last updated 2024-08-06 07:06:34
Assigner apple
CVSS score not scored
State PUBLISHED

Description

The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a session in which no Server Key Exchange message has been sent, which allows remote attackers to have an unspecified impact via crafted TLS data.